summaryrefslogtreecommitdiffstats
path: root/app/controllers/groups_controller.rb
blob: 0ca636e19ed7c290ea3e64c47ebd516272f36d4a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
# frozen_string_literal: true

# Redmine - project management software
# Copyright (C) 2006-2021  Jean-Philippe Lang
#
# This program is free software; you can redistribute it and/or
# modify it under the terms of the GNU General Public License
# as published by the Free Software Foundation; either version 2
# of the License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.

class GroupsController < ApplicationController
  layout 'admin'
  self.main_menu = false

  before_action :require_admin, :except => [:show]
  before_action :find_group, :except => [:index, :new, :create]
  accept_api_auth :index, :show, :create, :update, :destroy, :add_users, :remove_user

  require_sudo_mode :add_users, :remove_user, :create, :update, :destroy, :edit_membership, :destroy_membership

  helper :custom_fields
  helper :principal_memberships

  def index
    respond_to do |format|
      format.html do
        scope = Group.sorted
        scope = scope.like(params[:name]) if params[:name].present?

        @group_count = scope.count
        @group_pages = Paginator.new @group_count, per_page_option, params['page']
        @groups = scope.limit(@group_pages.per_page).offset(@group_pages.offset).to_a
        @user_count_by_group_id = user_count_by_group_id
      end
      format.api do
        scope = Group.sorted
        scope = scope.givable unless params[:builtin] == '1'
        @groups = scope.to_a
      end
    end
  end

  def show
    return render_404 unless @group.visible?

    respond_to do |format|
      format.html do
        render :layout => 'base'
      end
      format.api
    end
  end

  def new
    @group = Group.new
  end

  def create
    @group = Group.new
    @group.safe_attributes = params[:group]

    respond_to do |format|
      if @group.save
        format.html do
          flash[:notice] = l(:notice_successful_create)
          redirect_to(params[:continue] ? new_group_path : groups_path)
        end
        format.api do
          render(:action => 'show', :status => :created,
                 :location => group_url(@group))
        end
      else
        format.html {render :action => "new"}
        format.api  {render_validation_errors(@group)}
      end
    end
  end

  def edit
  end

  def update
    @group.safe_attributes = params[:group]

    respond_to do |format|
      if @group.save
        flash[:notice] = l(:notice_successful_update)
        format.html {redirect_to_referer_or(groups_path)}
        format.api  {render_api_ok}
      else
        format.html {render :action => "edit"}
        format.api  {render_validation_errors(@group)}
      end
    end
  end

  def destroy
    @group.destroy

    respond_to do |format|
      format.html {redirect_to_referer_or(groups_path)}
      format.api  {render_api_ok}
    end
  end

  def new_users
  end

  def add_users
    @users = User.not_in_group(@group).where(:id => (params[:user_id] || params[:user_ids])).to_a
    @group.users << @users
    respond_to do |format|
      format.html {redirect_to edit_group_path(@group, :tab => 'users')}
      format.js
      format.api do
        if @users.any?
          render_api_ok
        else
          render_api_errors "#{l(:label_user)} #{l('activerecord.errors.messages.invalid')}"
        end
      end
    end
  end

  def remove_user
    @group.users.delete(User.find(params[:user_id])) if request.delete?
    respond_to do |format|
      format.html {redirect_to edit_group_path(@group, :tab => 'users')}
      format.js
      format.api {render_api_ok}
    end
  end

  def autocomplete_for_user
    respond_to do |format|
      format.js
    end
  end

  private

  def find_group
    @group = Group.find(params[:id])
  rescue ActiveRecord::RecordNotFound
    render_404
  end

  def user_count_by_group_id
    h = User.joins(:groups).group('group_id').count
    h.keys.each do |key|
      h[key.to_i] = h.delete(key)
    end
    h
  end
end